So, I got this to work. In the role to which the user gets assigned after logging in, specify the URL of your OWA server as the custom start page. Make sure that there is no custom rewriting rule which causes the URL to not be rewritten. Then, add a Basic Auth / NTLM SSO policy which specifies Basic Auth with the resource specified as the URL of your OWA server. Choose to enable intermediation using system credentials. Worked great - logged into the IVE, and the next page I saw was my OWA InBox. Not sure it's important, but we run OWA 2003. Ken
... View more